Task-and-role-based access-control model for computational grid

被引:0
|
作者
龙涛
机构
[1] College of Computer Science Huazhong University of Science and Technology
[2] Wuhan 430074 P.R. China
关键词
computational grid; task-and-role-based access control; grid security; role assignment;
D O I
暂无
中图分类号
TP393.01 [];
学科分类号
081201 ; 1201 ;
摘要
Access control in a grid environment is a challenging issue because the heterogeneous nature and independent administration of geographically dispersed resources in grid require access control to use fine-grained policies. We established a task-and-role-based access-control model for computational grid (CG-TRBAC model), integrating the concepts of role-based access control (RBAC) and task-based access control (TBAC). In this model, condition restrictions are defined and concepts specifically tailored to Workflow Management System are simplified or omitted so that role assignment and security administration fit computational grid better than traditional models; permissions are mutable with the task status and system variables, and can be dynamically controlled. The CG-TRBAC model is proved flexible and extendible. It can implement different control policies. It embodies the security principle of least privilege and executes active dynamic authorization. A task attribute can be extended to satisfy different requirements in a real grid system.
引用
收藏
页码:249 / 255
页数:7
相关论文
共 50 条
  • [21] A MODEL OF ENFORCEMENT RELATIONSHIPS AMONG DATABASE ACCESS-CONTROL DEPENDENCIES
    HARTSON, HR
    BALLIET, EJ
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 1983, 3 (03) : 201 - 217
  • [22] THE RALEIGH ACTIVITY MODEL - INTEGRATING VERSIONS, CONCURRENCY, AND ACCESS-CONTROL
    KAY, MH
    RIVETT, PJ
    WALTERS, TJ
    [J]. LECTURE NOTES IN COMPUTER SCIENCE, 1992, 618 : 175 - 191
  • [23] Team and task based RBAC access control model
    Zhou, Wei
    Meinel, Christoph
    [J]. 2007 LATIN AMERICAN NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2007, : 84 - 94
  • [24] Research on Access-control Model in E-Government workflow
    Li Duan-Ming
    Li Yu-Xiang
    [J]. ICFCSE 2011: 2011 INTERNATIONAL CONFERENCE ON FUTURE COMPUTER SUPPORTED EDUCATION, VOL 1, 2011, : 474 - 477
  • [25] Runtime Support for Rule-Based Access-Control Evaluation through Model-Transformation
    Martinez, Salvador
    Garcia, Jokin
    Cabot, Jordi
    [J]. PROCEEDINGS OF THE 2016 ACM SIGPLAN INTERNATIONAL CONFERENCE ON SOFTWARE LANGUAGE ENGINEERING (SLE'16), 2016, : 57 - 69
  • [26] The New Grid Task Attemper Layer Model Based on Role
    Zhong, Zhou Xin
    [J]. INFORMATION AND AUTOMATION, 2011, 86 : 475 - 481
  • [27] Handling Role-based Access Control in the Digital Grid
    Fries, Steffen
    Falk, Rainer
    Bisale, Chaitanya
    [J]. SEVENTH INTERNATIONAL CONFERENCE ON SMART GRIDS, GREEN COMMUNICATIONS AND IT ENERGY-AWARE TECHNOLOGIES (ENERGY 2017), 2017, : 27 - 32
  • [28] Towards an Attribute-Based Authorization Model with Task-Role-Based Access Control for WfMS
    Liu, Kui
    Zhou, Zhurong
    Chen, Qianguo
    Yang, Xiaoli
    [J]. 2015 IEEE 16TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT), 2015, : 361 - 371
  • [29] ACCESS-CONTROL AND VERIFICATION IN PETRI-NET-BASED HYPERDOCUMENTS
    STOTTS, PD
    FURUTA, R
    [J]. COMPASS 89 : PROCEEDINGS OF THE FOURTH ANNUAL CONFERENCE ON COMPUTER ASSURANCE: SYSTEMS INTEGRITY, SOFTWARE SAFETY AND PROCESS SECURITY, 1989, : 49 - 55
  • [30] DYNAMIC ACCESS-CONTROL SCHEME BASED ON THE CHINESE REMAINDER THEOREM
    WU, TC
    WU, TS
    HE, WH
    [J]. COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 1995, 10 (02): : 92 - 99